Solved

Certificates for ADFS and O 365

Posted on 2014-07-18
3
371 Views
Last Modified: 2014-07-18
We currently have a wild card certificate in our Exchange invironment. However, is it best to use a specific certicate for ADFS such fs01.domain.com? And if Clustering Load Balance is being used, would it also be best to incorporate the cluster name in the Certificate? or would our current wild card cert be sufficient?
0
Comment
Question by:K Anthony O365
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 4

Accepted Solution

by:
Philip Portnoy earned 250 total points
ID: 40205440
Well, wildcart cert is definitely sufficient for anything, that you're using inside of your domain, because anything actually has a name of *.domain.com.

But I prefer (due to security measures) to use a separate cert for every server. For example for Exchange I'd use 1 cert, that includes Exchange internal and external URLs, NLB DNS name and autodiscover URLs. You don't really need to have  mailbox server names in the cert. This answers your first and third question: yes, it's better to use separate certs for every service (due to security requirements, for example if you need to recall one of the certs you don't need to replace it everywhere); and yes, I'd recommend to incorporate cluster name into the certificate (if this cluster is used for the same service, that requires this cert), though I wouldn't do it if cluster is for ADFS and cert is for Exchange.
0
 
LVL 37

Assisted Solution

by:Mahesh
Mahesh earned 250 total points
ID: 40205653
With ADFS there is ADFS farm which requires ADFS service name which will be get published on internet
You can use same wildcard certificate on ADFS server as long as ADFS service name FQDN match the one in certificate.
If you have multiple ADFS servers in adfs farm, No matter which certificate you use, you need to export same certificate with private key on one adfs server and need to import it on another ADFS servers and ADFS proxy servers if any.
0
 

Author Closing Comment

by:K Anthony O365
ID: 40205894
Very helpful. Thanks!!
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question